Description
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about any standard form field of any form submission.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12722 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about any standard form field of any form submission. |
References
History
Sat, 21 Dec 2024 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-12-20T23:47:22.901Z
Reserved: 2023-02-06T21:15:05.129Z
Link: CVE-2023-0694
Updated: 2024-08-02T05:17:50.331Z
Status : Modified
Published: 2023-06-09T06:15:51.780
Modified: 2024-11-21T07:37:38.597
Link: CVE-2023-0694
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD